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Abstract 

In this paper we study a subclass of pebble automata (PA) for data 
languages for which the emptiness problem is decidable. 

Namely, we introduce the so-called top view weak PA. Roughly 
speaking, top view weak PA are weak PA where the equality test is 
performed only between the data values seen by the two most re- 
cently placed pebbles. The emptiness problem for this model is de- 
cidable. We also show that it is robust: alternating, nondeterministic 
and deterministic top view weak PA have the same recognition power. 
Moreover, this model is strong enough to accept all data languages 
expressible in Linear Temporal Logic with the future-time operators, 
augmented with one register freeze quantifier. 



1 Introduction 



Regular languages are clearly one of the most important concepts in computer 
science. They have applications in basically all branches of computer science. 
It can be argued that the following properties contributed to their success. 

1. Expressiveness: In many settings regular languages are powerful enough 
to capture the kinds of patterns that have to described. 

*This work was done while the author was in the Department of Computer Science in 
Technion - Israel Institute of Technology. It can also be found as a technical report in [17] . 
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2. Decidability: Unlike many general computational models, the mech- 
anisms associated with regular languages allow one to perform auto- 
mated semantic analysis. 

3. Efficiency: The model checking problem, that is, testing whether a 
given string is accepted by a given automaton can be solved in polyno- 
mial time. 

4. Closure properties: The regular languages possess all important closure 
properties. 

5. Robustness: The class of regular languages has many characterizations. 
For example, various extensions like nondeterminism and alternation 
do not add any expressive power. Another characterizations include 
regular expressions, monoids and monadic second-order logic. 

Moreover, similar notion of regularity has been successfully generalized 
to other kind of structures, including infinite strings and finite, as well as 
infinite, ranked or unranked, trees. Most recent applications of regular lan- 
guages (on infinite strings and finite, unranked trees, respectively) are in 
model checking and XML processing. 

• In model checking a system is a finite state one and properties are 
specified in a logic like LTL. Satisfiability of a formula in a system is 
checked on the structure that is the product of the system automaton 
and an automaton corresponding to the formula. The step from the 
"real" system to its finite state representation usually involves many 
abstraction, especially with respect to data values (variables, process 
numbers, etc.). Often their range is restricted to a finite domain. 
Even though this approach has been successful and found its way into 
large scale industrial applications, the finite abstraction have some in- 
herent shortcomings. As as example, n identical processes with m 
states each give rise to an overall model of size m n . If the number of pro- 
cesses is unbounded or unknown in advance, the finite state approach 
fails. Previous work has shown that even in such setting decidability 
can be obtained by restricting the problem in various ways [TJ [7]. 

• In XML document processing, regular concepts occur in various con- 
texts. First, most applications restrict the structure of the allowed doc- 
uments to conform to a certain specification (DTD or XML schema), 
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which can be modeled as a regular tree language. Second, navigation 
(XPath) and transformation (XSLT) languages are tightly connected 
to various tree automata models and other regular description mecha- 
nism, see, for example, [12J. 

All these approaches concentrate on the structure of the XML docu- 
ments and ignore the attribute and text values. From a database point 
of view, this is not completely satisfactory, because a schema should 
allow one not only to describe the structure of the data, but also to 
define restrictions on the data values via integrity constraints such as 
key or inclusion constraints. There exist a work addressing this prob- 
lem [2J, but like in the case of model checking, the methods rely heavily 
on a case-to-case analysis. 

So, in the above settings, the finite state abstraction leads to interesting 
results, but does not address all problems arising in applications. In both 
cases, it would be already a big advance, if each position, in either a string 
or a tree, could carry a data value, in addition to its label. 

This paper is part of a broader research program which aims at studying 
such extensions in a systematic way. As any kind of operations on the infinite 
domain quickly leads to undecidability of basic processing tasks (even a linear 
order on the domain is harmful), we concentrate on the setting, where data 
values can only be tested for equality. Furthermore, in this paper we only 
consider finite data strings, that is, finite strings, where each position carries 
a label from a finite alphabet and a data value from an infinite domain. 
Recently, there has been a significant amount of work in this direction, see [21 

HEHEEUCESl. 

Roughly speaking, there are two approaches to studying data languages: 
logic and automata. Below is a brief survey on both approaches. For a more 
comprehensive survey, we refer the reader to |15j . The study of data lan- 
guages, which can also be viewed as languages over infinite alphabets, starts 
with the introduction of finite-memory automata (FMA) in [9J, which are 
also known as register automata (RA). The study of RA was continued and 
extended in [13], in which pebble automata (PA) were also introduced. Each 
of both models has its own advantages and disadvantages. Languages ac- 
cepted by FMA are closed under standard language operations: intersection, 
union, concatenation, and Kleene star. In addition, from the computational 
point of view, FMA are a much easier model to handle. Their emptiness 
problem is decidable, whereas the same problem for PA is not. However, the 
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PA languages possess a very nice logical property: closure under all boolean 
operations, whereas FMA languages are not closed under complementation. 

Later in [1] first-order logic for data languages was considered, and, in 
particular, the so-called data automata was introduced. It was shown that 
data automata define the fragment of existential monadic second order logic 
for data languages in which the first order part is restricted to two variables 
only. An important feature of data automata is that their emptiness problem 
is decidable, even for the infinite words, but is at least as hard as reachability 
for Petri nets. The automata themselves always work nondeterministically 
and seemingly cannot be determinized, see [3]. It was also shown that the 
satisfiability problem for the three- variable first order logic is undecidable. 

Another logical approach is via the so called linear temporal logic with n 
register freeze quantifier over the labels E, denoted LTL^(S,X, U), see j6]. It 
was shown that one way alternating n register automata accept all LTL^(S, X, U) 
languages and the emptiness problem for one way alternating one register 
automata is decidable. Hence, the satisfiability problem for LTL{(S,X,U) 
is decidable as well. Adding one more register or past time operators to 
LTL{(S,X,U) makes the satisfiability problem undecidable. 

In this paper we continue the study of PA, which are finite state automata 
with a finite number of pebbles. The pebbles are placed on/lifted from the 
input word in the stack discipline - first in last out - and are intended to 
mark positions in the input word. One pebble can only mark one position 
and the most recently placed pebble serves as the head of the automaton. 
The automaton moves from one state to another depending on the current 
label and the equality tests among data values in the positions currently 
marked by the pebbles, as well as, the equality tests among the positions of 
the pebbles. 

Furthermore, as defined in [13], there are two types of PA, according to 
the position of the new pebble placed. In the first type, the ordinary PA, 
also called strong PA, the new pebbles are placed at the beginning of the 
string. In the second type, called weak PA, the new pebbles are placed at 
the position of the most recent pebble. Obviously, two-way weak PA is just 
as expressive as two-way ordinary PA. However, it is known that one-way 
nondeterministic weak PA are weaker than one-way ordinary PA, see [T3~| 
Theorem 4.5.]. 

We show that the emptiness problem for one-way weak 2-pebble automata 
is decidable, while the same problem for one-way weak 3-pebble automata 
is undecidable. We also introduce the so-called top view weak PA. Roughly 
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speaking, top view weak PA are one-way weak PA where the equality test is 
performed only between the data values seen by the two most recently placed 
pebbles. Top view weak PA are quite robust: alternating, nondeterministic 
and deterministic top view weak PA have the same recognition power. To 
the best of our knowledge, this is the first model of computation for data 
language with such robustness. It is also shown that top view weak PA 
can be simulated by one-way alternating one-register RA. Therefore, their 
emptiness problem is decidable. Another interesting feature is top view weak 
PA can simulate all LTLj(S,X,U) languages, and the number of pebbles 
needed to simulate such LTL sentences corresponds linearly to the so called 
free quantifier rank of the sentences, the depth of the nesting level of the 
freeze operators in the sentence. 

This paper is organized as follows. In Section [2] we review the models 
of computations for data languages considered in this paper. Section [3] and 
Section 0] deals with the decidability and the complexity issues of weak PA, 
respectively. In Section [6] we introduce top view weak PA. We also introduce 
a simple extension to top view weak PA, called unbounded top view weak 
PA, in which the number of pebbles is unbounded in Section [7] Finally, we 
end our paper with a brief observation in Section [HJ This paper is augmented 
with appendices that contain most of the omitted details. 



2 Models of computations 

In Subsections 12.11 and 12.21 we recall the definition of weak PA from (13] , 
and review the strict hierarchy of weak PA languages established in [16]. In 
Subsection 12.31 we recall the temporal logical framework for data languages. 

We will use the following notation. We always denote by E a finite al- 
phabet of labels and by D an infinite set of data values. A H-data word 
w = la J ial) ' ' ' UJ * s a ^ n ^ e sequence over E x D, where <7j G E and 
Oi G ID. A H-data language is a set of E-data words. The idea is that 
the alphabet E is accessed directly, while data values can only be tested for 
equality. 

We assume that neither of E and ID contain the left-end marker < or the 
right-end marker >. The input word to the automaton is of the form <w>, 
where < and > mark the left-end and the right-end of the input word. 

We will also use the following notations. For w = (^) • • ■ y), 

Proj s (» = <7i -••<7 n 
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Proj^O) = af-a n 
Cont s (u;) = {(Ti, . . . ,a n } 
Contstw) = {ai, ...,a n } 

Finally, the symbols i/, i?, c, . . ., possibly indexed, denote labels in £ and 
the symbols a,b,c,d, . . ., possibly indexed, denote data values in 2D. 

2.1 Pebble automata 

Definition 1 (See [T3"l Definition 2.3]) A one-way alternating weak k-pebble 
automaton or, in short, k-PA, over £ is a system A = (E,Q,q , F, p,,U) 
whose components are defined as follows. 

• Q, qo G Q and F C Q are a finite set of states, the initial state, and 
the set of final states, respectively; 

• U C Q — F is the set of universal states; and 

• n C C x T> is the transition relation, where 

— C is a set whose elements are of the form (i, a, V, q) where 1 < % < 
fc, (7 £ £, V C {« + 1, . . . , /&} and q E Q; and 

— T> is a set whose elements are of the form (g, act), where q G Q 
and act G {stay, right, place-pebble, lift-pebble}. 

Elements of /i will be written as {i, a, V, q) — > {p, act). 

Remark 2 Note that the pebble numbering that differs from that in [13] . 
In the above definition we adopt the pebble numbering from [5] in which the 
pebbles placed on the input word are numbered from k to i and not from 1 
to i as in [13]. The reason for this reverse numbering is that it allows us to 
view the computation between placing and lifting pebble i as a computation 
of an (i — l)-pebble automaton. 

Furthermore, the automaton is no longer equipped with the ability to 
compare positional equality, in contrast with the ordinary PA introduced 
in |13j . Such ability no longer makes any difference because the new pebbles 
are placed in the "weak" manner. 
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Given a word w = (^) • • • (^ n ) 6 (Ex X))*, a configuration of A on <w> 
is a triple [i, q, 9], where % G {1, . . . , k}, q G Q, and : {i, i + 1, . . . , k} — > 
{0, 1, . . . , n, n + 1}, where and n + 1 are positions of the end markers < 
and >, respectively. The function 9 defines the position of the pebbles and 
is called the pebble assignment. The initial configuration is 70 = [k,q ,9o], 
where 9 (k) — is the initial pebble assignment. A configuration [i, q, 9} with 
q G F is called an accepting configuration. 

A transition (i,a,V,p) — > f3 applies to a configuration [j,q,9], if 

(1) % = j and p = q, 

(2) V = {I > i : a 6 (i) = a e ^}, and 

(3) ag(i) = a. 

Next we define the transition relation h A as follows: [i, q, 9} \- A [i' , q', 9'], 
if there is a transition a — > (p, act) G /i that applies to [i, q, 9] such that 
q' = p, for all j > i, Q'(j) = 9(j), and 

- if act = stay, then i' — i and 9'(i) = 0(i), 

- if act = right, then i' — % and 9'{%) = 9{i) + 1, 

- if act = lift-pebble, then i' — i + 1, 

- if act = place-pebble, then i' = 1 — 1, 9'(i — l) = 9(i) and 9'(i) = 9(i). 

As usual, we denote the reflexive transitive closure of \- A by When the 
automaton A is clear from the context, we shall omit the subscript A. 

The acceptance criteria is based on the notion of leads to acceptance 
below. For every configuration 7 = [i, q, 9], 

• if q G F, then 7 leads to acceptance; 

• if q G U, then 7 leads to acceptance if and only if for all configurations 
7' such that 7 h 7', 7' leads to acceptance; 

• if q ^ F U U, then 7 leads to acceptance if and only if there is at least 
one configuration 7' such that 7 h 7', and 7' leads to acceptance. 
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A E-data word w G (S x D)* is accepted by A, if 70 leads to acceptance. 
The language L(A) consists of all data words accepted by A. 

The automaton A is nondeterministic, if the set U — 0, and it is deter- 
ministic, if there is exactly one transition that applies for each configuration. 
It turns out that weak PA languages are quite robust. 

Theorem 3 For all k > 1, alternating, non- deterministic and deterministic 
weak k-PA have the same recognition power. 

The proof is quite standard. For the details of the proof, we refer the reader 
to Appendix ID1 

Next, we define the hierarchy of languages accepted by PA. For k > 1, 
We define the following classes of languages. 

wPAfc = {L : L is accepted by a weak /c-PA}; and 
wPA = |JwPA fc 

k>\ 

This example will be useful in the subsequent section. 

Example 4 Consider a S-data language defined as follows. A S-data 
word w = ■ ■ ■ G if and only if for all i,j — 1, . . . , n, if aj = dj, 
then o"j = CTj. That is, w G if and only if whenever two positions in w 
carry the same data value, their labels are the same. 

The language is accepted by weak 2-PA which works in the following 
manner. Pebbles 2 iterates through all possible positions in w. At each 
iteration, pebble 1 is placed and scans through all the positions to the right 
of pebble 2, checking whether there is a position with the same data value of 
pebble 2. If there is such position, then the labels seen by pebbles 1 and 2 
are the same. 

2.2 Strict hierarchy of weak PA languages 

In this section we review an example of data language introduced in [16J. 
It will be useful in establishing our definability results for LTL|;(E, X, U) lan- 
guages. 
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Let S = {a} be a singleton alphabet. For an integer m > 1, the language 
consists of S-data words of the form 




• for each i = 0, 1, . . . , m — 1, aj ^ Oi+ij 

• for each i = 1, . . . , m — 1, a, G" Contxi(wj). 
The language 7£ + is defined as 

n+= U 

771=1,2,... 

Theorem 5 (^ee ITb} Lemma 18].) For each k = 1, 2, . . ., 

1. IZk G wiMfc and ^ wPA^; 

2. wPA k C «;PA fe+ i. 

2.3 Linear temporal logic with one register freeze quan- 
tifier 

In this section we recall the definition of Linear Temporal Logic (LTL) with 
one register freeze quantifier [6]. We consider only one-way temporal opera- 
tors "next" X and "until" U, and do not consider their past time counterparts. 

Let E be a finite alphabet of labels. Roughly, the logic LTL{(£, X, U) is 
standard LTL augmented with a register to store a data value. Formally, the 
formulas are defined as follows. 

• Both True and False belong to LTL|(S,X,U). 

• The empty formula e belongs to LTL|(S, X, U). 

• For each a G S, a is in LTLj(E,X,U). 

• If <p, ip are in LTL|(S,X,U), then so are -up, <p\/ ip and ip A ip. 

• t is in LTL|(S,X,U). 



9 



• If tp is in LTL|(S,X,U), then so is Xtp. 

• If tp is in LTL|(S, X, U), then so is 1 tp. 

• If tp,ip are in LTL}(E, X, U), then so is tp\]tp. 

Intuitively, the predicate j is intended to mean that the current data value 
is the same as the data value in the register, while j tp is intended to mean 
that the formula tp holds when the register contains the current data value. 
This will be made precise in the definition of the semantics of LTL{(S,X, U) 
below. 

An occurrence of j within the scope of some freeze quantification j is 
bounded by it; otherwise, it is free. A sentence is a formula with no free 
occurrence of f- 

Next we define the freeze quantifier rank of a sentence tp, denoted by 
fqr(v?). 

• For each a G £, fqr(cr) = 0. 

• fqr(True) = fqr(False) = fqr(f) = 0. 

• fqr(Xy?) = fqr(-i^) = fqr(<p), for every tp in LTL}(£,X,U). 

• fqr(tp V tp) = fqr((/9 A ip) — fqr(tp\Jijj) = max(fqr(</?), fqr(*0)), for every tp 
and ip in LTL}(E,X,U). 

• f qr Q tp) = fqr(v?) + 1, for every tp in LTLj(£, X,U). 

Finally, we define the semantics of LTLj(£, X, U). Let w = (£) • • • (^) be 
a S-data word. For a position % — 1, . . . , n, a data value a and a formula </? 
in LTL|(S, X, U), w, % |= a tp means that tp is satisfied by w at position % when 
the content of the register is a. As usual, w, % \/= a tp means tp is not satisfied 
by w at position % when the content of the register is a. The satisfaction 
relation is defined inductively as follows. 

• w,i \= a e for all i — 1, 2, . . . , n and a e 2). 

• iu, i |= a True and w, i ^ a False, for alH = 1, 2, 3, . . . and a G 3D. 

• w,i \= a o if and only if <jj = cr. 

• w, i \= a tp V ip if and only if w, i |= a y9 or w, i |= a ■?/ ; - 
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• w,i \= a (p A if) if and only if w,i \= a <p and w, i |= a ip- 

• w, i |= a -up ^ an d only if w, i \t= a ip. 

• w,i\= a Xy? if and only if 1 < i < \w\ and w, i + 1 |= a 99. 

• w, i |= a <y9U^ if and only if there exists j > % such that 

- w, j \= a tp and 

- w,f \= a ip, for all / = i, . . . ,j - I. 

• w, i \= a lip if and only if w, i \= ai V 9 

• w, i |= a I if and only if a = dj. 

For a sentence in LTL{(S,X, U), we define the S-data language -^(v 9 ) by 

L(<p) = {w I w, 1 |= a y9 for some a G D}. 

Note that since is a sentence, all occurrences of 1" in are bounded. Thus, 
it makes no difference which data value a is used in the statement w, 1 |= a <p 
of the definition of L(ip). 

3 Decidability and undecidability of weak PA 

In this section we will discuss the decidability issue of weak PA. We show that 
the emptiness problem for weak 3-PA is undecidable, while the same problem 
for weak 2-PA is decidable. The proof of the decidability of the emptiness 
problem for weak 2-PA will be the basis of the proof of the decidability of 
the same problem for top view weak PA. 

Theorem 6 The emptiness problem for weak 3-PA is undecidable. 

Proof. The proof is very similar to the proof of the undecidability of the 
emptiness problem for weak 5- PA in [13J. We observe that the same proof 
can be easily adopted to weak 3-PA. The details are provided below. It uses 
a reduction from the Post Correspondence Problem (PCP), which is well 
known to be undecidable [8]. An instance of PCP is a sequence of pairs 
(xx, yx), . . . , (x n , y n ), where each 
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This instance has a solution if there exist indexes i±, . . . , i m G {1, . . . , n} 
such that Xi x ■ ■ ■ x im = y ix ■ ■ ■ y im . The PCP asks whether a given instance of 
the problem has a solution. 

In the following we show how to encode a solution of an instance of PCP 
into a data word which possesses properties that can be checked by a weak 
3- PA. Let £ = {1, . . . , n, a, (3, $}. We denote by Xi = v i X • • • u^., for each 
i = 1, ... Each string Xi is encoded as Enc(xj) = ■ ■ ■ (^'j*) where 
Oj ; i, . . . , are pairwise different. 

The string x ix x i2 ■ ■ -x im can be encoded as 

Enc(x h ,x i2 ,...,x im ) = ^^Enc(rr il )^^Enc(xi 2 )--- ^ m ^Enc(x im ) 

where all the data values that appear in it are pairwise different. Note that 
even if ij = iy for some j,j', the data values that appear in Enc(xj j ) do not 
appear in Enc(xi ,) and vice versa. The idea is each data value is used to 
mark a place in the string. 

Similarly, the string y^y^ ■ • • y^ can be encoded as 

Enc(y jl , y j2 , ...,%-,) = Enc( %1 ) ^ Enc( %2 ) • • • Q Enc(y Ji ) 

where the data values that appear in it are pairwise different. 
Now the data word 



I) Enc(Xll) ' ' ' Gj Enc{XiJ Q u ) Encfe) • • • u 



constitutes a solution to the instance of PCP if and only if 

hk-'-im = jlj2---jl (1) 

Proj E (Enc(a: il )---Enc(a: i J) = Pr0 Js( Enc (%i) ' ' ' Enc (%'J) ( 2 ) 

Now, in order to able to check such property with weak 3-PA, we demand 
the following additional criteria. 

1. b x ■ ■ -b m = ci • • -ci] 

2. Proj^EncfoJ • • • Enc(x im )) = Proj S) (Enc(y jl ) • • • Enc(y j( )) 
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3. For any two positions hi and h 2 where hi is to the left of the delimiter 
( $ ) and h% is to the right of the delimiter ( $ ) , if both of them have the 
same data value, then both of them are labelled with the same label. 

All the Criterias (l)-(3) imply Equations [T] and [2J 

Because the data values that appears in Proj J) (Enc(xj 1 ), . . . , Enc(x im )) are 
pairwise different, all of them are checkable by three pebbles in the "weak" 
manner. For example, to check Criteria (1), the automaton does the follow- 
ing. 

• Check that hi — C\. 

• Check that for each i = 1, . . . ,m — 1, there exists j such that a^a^i = 
bjbj+i. 

It can be done by placing pebble 3 to read Oj and pebble 2 to read Oj + i, 
then using pebble 3 to search on the other side of $ for the index j. 

• Finally, check that b m = q. 

Criteria (2) can be checked similarly and Criteria (3) is straightforward. The 
reduction is now complete and we prove that the emptiness problem for weak 
3-PA is undecidable. □ 

Now we are going to show that the emptiness problem for weak 2-PA 
is decidable. The proof is by simulating weak 2-PA by one-way alternating 
one register automata (1-RA). In fact, the simulation can be easily general- 
ized to arbitrary number of pebbles. That is, weak A;-PA can be simulated 
by one-way alternating {k — 1)-RA. This result settles a question left open 
in [13]: Can weak PA be simulated by alternating RA? We refer the reader 
to Appendix [C] for the details of the proof. 

Theorem 7 For every weak 2-PA A, there exists a one-way alternating 1- 
RA A' such that L(A) = L(A'). Moreover, the construction of A' from A is 
effective. 

Now, by Theorem we immediately obtain the decidability of weak 2-PA 
because the emptiness problem for one-way alternating 1-RA is decidable 
Theorem 4.4]. 

Corollary 8 The emptiness problem for weak 2-PA is decidable. 
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We devote the rest of this section to the proof of Theorem 
Let A = (Q, qo, (jl, F) be a weak 2-PA. We assume that A is deterministic. 
Furthermore, we normalize the behavior oL4 as follows. 

• Pebble 1 is lifted only after it reads the right-end marker symbol t>. 

• Only pebble 2 can enter a final state and it does so after it reads the 
right-end marker >. 

• Immediately after pebble 2 moves right, pebble 1 is placed. 

• Immediately after pebble 1 is lifted, pebble 2 moves right. 

On input word w = (^) • ■ ■ (^"), the run of A on <w> can be depicted as 
a tree shown in Figure [H 




if. 



Figure 1: The tree representation of a run of A on w 



idj ' ' ' (d n ) ■ 



The meaning of the tree is as follows. 
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q Q ,qi, . . . , q n , q n+ i are the states of A when pebble 2 is the head pebble 
reading the positions 0, 1, ... , n, n + 1, respectively, that is, the symbols 
<> (£)>•••>(£)>>> respectively. 

qj is the state of A after pebble 2 reads the symbol >. 

For 1 < i < j < n, p^j is the state of A when pebble 1 is the head 
pebble above the position j while pebble 2 is above the position i. 

For 1 < i < n, the state pi is the state of A immediately after pebble 1 
is lifted and pebble 2 is above the position i. 

It must be noted that there is a transition (2, a iy 0,Pi) — > (ft+i, right) 
applied by A that is not depicted in the figure. 



9/- 

Qn+l 




'(Pn,Pn) 





A! "verifies" the guess p\ 
4 



'(pi,Pi) 



(Pn,n ) Pn ) 




*(Pl,n+l,Pl) 



(Pl,n,Pl) 




*(Pl,2,Pl) 



A' "guesses" the state pi and then "splits" 



91 
< 
9o • 



Figure 2: The corresponding run of A' to the one in Figure [3j 
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Now the simulation of A by a one-way alternating 1-RA A' becomes 
straightforward by transforming the tree in Figure [3] into a tree depicting the 
computation of A' on the same word w. 

Roughly, the automaton A' is defined as follows. 

• The states of A' are elements of Q U (Q x <5)0; 

• the initial state is qo; and 

• the set of final states is F U {(p,p) '■ p G Q}. 

For each placement of pebble 1 on position i, the automaton performs the fol- 
lowing "Guess-Split- Verify" procedure which consists of the following steps. 

1. From the state q iy A' "guesses" the state in which pebble 1 is eventually 
lifted, i.e. the state pi, and stores it in its internal state. 

That is, A' enters into the state (qi,Pi). 

2. A' "splits" its computation (conjunctively) into two branches. 

• In one branch, assuming that the guess p\ is correct, A moves right 
and enters into the state qi+i, simulating the transition (2, 0,Pi) — > 

right). After this, it recursively performs the Guess-Split- 
Verify procedure for the next placement of pebble 1 on position (z+ 

I)- 

• In the other branch A' stores the data value di in its register and 
simulates the run of pebble 1 on g») ■ • • (£) to "verify" that the 
guess Pi is correct. 

That is, A' accepts only if it ends in the state (pi,Pi). 
Figure [3] shows the corresponding run of A' on the same word. 

4 Complexity of weak 2-PA 

In this subsection we are going to determine the time complexity of three 
specific problems related to weak 2-PA. 

Actually A. needs some other auxiliary states. However, for the intuitive explanation 
here the set Q U (Q x Q) suffices. We refer the reader to Appendix [Cl for the details. 
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Emptiness problem. The emptiness problem for weak 2-PA. That is, given 
a weak 2-PA A, is L(A) = 0? 

Labelling problem. Given a weak 2-PA A over the labels E and a sequence 
of data values d± • • • d n G 2) n , is there a sequence of labels o\ • • • a n G E n 
such that 6^)? 

Data value membership problem. Given a weak 2-PA A over the labels 
E and a sequence of finite labels <7i • • • a n G E n , is there a sequence of 
data values d\ ■ ■ ■ d n £ D n such that (£) • • • G L(i)? 

The emptiness problem, as we have seen in the previous section, is decid- 
able. The labelling and data value membership problem are definitely de- 
cidable. To solve the labelling problem, one simply iterates all possible se- 
quence a i • • • a n G E™ and runs A to check whether (£) • • • (£) G L(A). 
Such straightforward algorithm requires 0(|S| ra • n 2 ) computational steps. 
Similarly, to solve the data value membership problem, one can iterate 
all possible sequence of data values d\ - ■ -d n and run A to check whether 
(dj) ' ' ' (d") ^ L(A). Since the word is of length n, one simply needs to 
consider up to n different data values. Such algorithm takes 0(n n ■ n 2 ) com- 
putational steps. 

We are going to show that the emptiness problem is not primitive re- 
cursive, while both the labelling and data value membership problems are 
NP-complete. 

We start the proof with a few simple examples of languages accepted by 
weak 2-PA. Though simple, they are very crucial in determining the com- 
plexity of the emptiness problem for weak 2-PA. 

Example 9 Let E = {a, [3}. We define the E-data language L inc which 
consists of the data words of the following form: 

Ci) (a m ) Gi) (&„)' 

N v " v ' 

101 W2 

where 

• the data values a±, . . . , a m are pairwise different; 

• the data values b±, . . . , b n are pairwise different; 
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• Proj s (wi) = a m ; 

• Pro Js (^ 2 ) = f3 n - 

• Conts(u'i) C Cont2)(u»2). 

All these conditions can be checked by weak 2-PA. The intention of data 
words in L inc is to represent the inequality m < n. 

Example 10 Let E = {a, (3}. For a fixed / > 0, we define the language 
Linc,+i which consists of the data words of the following form: 




where 

• the data values a±, . . . ,a m are pairwise different; 

• the data values b±, . . . ,b n are pairwise different; 

• Proj E (wi) = a m ; 

• Pro Js («; 2 ) =f3 n - 

• For each dj G Contofwi), di^b\. 

• {ai, . . . ,a m } C {6 2 , . . -,b n }. 

Again, all these conditions can be checked by weak 2-PA. The intention of 
data words in L inCt+ i is to represent the inequality m + 1 < n. 

Example 11 Let S = {a, f3}. For a fixed / > 0, we define the language 
Linc^i which consists of the data words of the following form: 

d) Cm) 

N v v ' 

Wl W2 

where 
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• the data values ai, . . . , a m are pairwise different; 

• the data values b±, . . . , b n are pairwise different; 

• Proj s Oi) = a m ] 

• Proj E ( W2 ) = (3 n ; 

• The symbol a\ £ {bi, . . . , b n }; 

• For each i — 2, . . . , m, a$ e {61, . . . , b n }. 

Again, all these conditions can be checked by weak 2-PA. The intention of 
data words in L inc _i is to represent the inequality m — 1 < n. 

Theorem 12 The emptiness problem for weak 2-PA is not primitive recur- 
sive. 

Proof. The proof is by simulation of incrementing counter automata. It 
follows closely the proof of similar lower bound for one-way alternating 1- 
RA [6, Theorem 2.9]. It is known that the emptiness problem for incre- 
menting counter automata is decidable [HI Theorem 6], but not primitive 
recursive [H] . We refer the reader to Appendix |A] for the formal definition 
of incrementing counter automata. 

In short, an incrementing Z-counter automaton over S is an automaton 
with I counters, operates on words over S, and the value in each counter is 
allowed to erroneously increase, hence, the name incrementing. 

A configuration is a tuple (q, a, v) where q is a state, a is the current 
symbol read and v : {1, ...,£}—> N, where v(i) denotes the value stored in 
counter i. 

Now a configuration (q, v) can be encoded as a (Q U S U {ci, . . . , c/})-data 
word as follows. 

( q )(°)( Cl ) -( Cl )■■■(*)■■■( c ' X 

\dij \d 2 J V a i,i/ \ a i,'U(i)/ \ a i,iJ \ a i,v(i)J 

where the symbols a^i, . . . , a^ v ^ are pairwise different. The labels ci, . . . , q 
are used as pointers that the current data value is part of the encoding of 
the counters v(l), . . . , v(l), respectively. 
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Since the automaton allows for erroneous increment of values in each 
counter, we can check the validity of the application of each transition, like 
in Examples El [TO] and HU □ 

Now we are going to show the NP-completeness of the labelling problem. 
It is by a reduction from graph 3-colorability problem. 

Given an undirected graph G = (V,E), let V = {l,...,n} and E = 
. . . , (i m ,j m )}. We can take ■ ■ -imjm as the sequence of data val- 
ues. Then, we construct a weak 2-PA A over the alphabet E = {$r, $g,$b} 
that accepts data words of even length in which the following hold. 

• For all odd position x, the label on position x is different from the label 
on position x + 1. 

• For every two positions x and y, if they have the same data value, then 
they have the same label. 

Thus, the graph G is 3-colorable if and only if there exists o\ • • • o<im £ 
{$ R , #b}* such that 



Ci\ /cr 2 \ / cr 2m _i\ fa 2m 
h) \ im ) \jm 



e L(A), 



and the NP-completeness of the labeling problem follows. 

The NP-completeness of data value membership problem can established 
in a similar spirit. The reduction is from the following variant of graph 3- 
colorability, called 3-colorability with constraint. Given a graph G = (V, E) 
and three integers n r , n g , in unary form, can the graph G be colored with 
the colors R, G and B such that the numbers of vertices colored with R, G 
and B are n r , n g and ri&, respectively? 

The polynomial time reduction to data value membership problem is as 
follows. Let V = {1, . . .,n} and E = {{h,ji), (i m ,j m )}- 

We define S = {$r, $b, vi, ■ ■ ■ , v n\- We take 

v h v h ■ ■ ■ VimVjm pR"J ®RpG ■ • • $g$b ■ • • i^B y 

n r times n g times n b times 

as the sequence of finite labels. 

Then, we construct a weak 2-PA over E that accepts data words of the 
form 

( v n\( v h\ (Vim\ f u j m \ f&R\ f^R\f^c\ {$g\{$b\ [-&B 



, c l / \d\ ) \C m J \d m J \ a l/ \ a n r J \ a 'l J \ a 'n g J \ a l / \ a n b/ 
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where 



• v ix ,v h ,...,v irn ,v jm e {i/ a , ...,i/ n }; 

• in the sub-word Q 1 ) • • • (^ m ) Q m ), every two positions with the 
same labels have the same data value , see Example HJ 

• the data values ai, . . . , a„ r , a' 1; . . . , c4 , a", . . . , d' nh are pairwise different; 

• For each i = 1, . . . ,m, the data values q, di appear among ai, . . . , a nr , 
a[, . . . , a' ng , a", . . . , such that the following holds: 

— if Cj appears among ai, . . . , a nr , then dj appears among a{, . . . , a' n 
or a'(, ...,< 5 ; 

— if Cj appears among a^, ...,aj, , then c?j appears either among 
a u . . . ,a nr or a", . . . ,a" 6 ; and 

— if q appears among a", . . . , a^ b , then dj appears among cti, . . . , a nr 
or a[,...,a' ng . 

Note that we can store the integers r, g, b and m in the internal states A, 
thus, enable ^4 to "count" up to n r , n g , and m. We have each state for the 
numbers 1, . . . , n r , 1, . . . , n g , 1, . . . , n& and 1, . . . , m. Furthermore, the unary 
form of n r , n g and nj, is crucial here to ensure that the number of the states 
of A is still polynomial in the length of the input. 

Now the graph G is 3-colorable with constraint if and only if there exits 
c\d\ ■ ■ ■ c m d m ai ■ ■ ■ a nr a[ ■ ■ ■ a' ng a'( ■ ■ ■ o!' nb such that 

AO| (*r\ . . . (*r\ (*a\ . . . MA (*b\ . . . (*b\ 

J\ a lJ \ a n r J\ a 'lJ \ a 'n g /\ a l/ \ a n b J 

is accepted by A, and the NP-completeness of data value membership prob- 
lem follows. 

5 Top view weak k-PA 

In this section we are going to restrict the definition of weak k-PA so that 
its emptiness problem becomes decidable. Roughly speaking, top view weak 
PA are weak PA where the equality test is performed only between the data 
values seen by the last and the second last placed pebbles. That is, if pebble i 
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is the head pebble, then it can only compare the data value it reads with the 
data value read by pebble (z + 1). It is not allowed to compare its data value 
with those read by pebble i + 2, . . . , k. 

Formally, the transitions of top view weak k-PA A = (Q, qo, \i, F) are of 
the form 

(i, a, V, q) -> (</, act) 

where V is either or {i + 1}. 

The definition of top view weak k-PA is defined by setting 



in the definition of transition relation in Subsection 12.11 Note that top view 
weak 2- PA are just the same as weak 2- PA. We can also define the alternating 
version of top view weak k-PA. However, just like in the case of weak k-PA, 
alternating, nondeterministic and deterministic top view weak &;-PA have the 
same recognition power. 

Theorem 13 For every top view weak k-PA A, there is a one-way alternat- 
ing 1-RA A' such that L(A') = L(A). Moreover, the construction of A' is 
effective. 

Proof. The proof is a straightforward generalization of the proof of The- 
orem [3 Each placement of a pebble is simulated by "Guess-Split -Verify" 
procedure. Since each pebble i can only compare its data value with the 
one seen by pebble i + 1, A' does not need to store the data values seen by 
pebble i + 2, . . . , k. It only need to store the data value seen by pebble i + 
thus, one register suffices. □ 

Following Theorem [5TJ we immediately obtain the decidability of the 
emptiness problem for top view weak k-PA. 

Corollary 14 The emptiness problem for top view weak k-PA is decidable. 

Remark 15 Since the emptiness problem for ordinary 2- PA and for weak 
3- PA is already undecidable (See Theorem [6] and jlOl Theorem 4]), it seems 
that top view weak PA is a tight boundary of a subclass of PA languages for 
which the emptiness problem is decidable. 




0, if a<9(i+i) 7^ a 8(i) 

{i + 1}, if ao( i+ x) = a 6 (i) 
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Theorem 16 For every sentence ip G LTL^(T>, X, If), there exists a top view 
weak k-PA where k = fqr(ip) + 1, such that L(A^) = L(ip). 

Proof. Let ip be an LTL^(£,X, U) sentence. We construct an alternating top 
view weak k-PA where k = fqr(^) + 1 such that given a data word w, the 
automaton A$ checks whether w, 1 |= ip. A^ accepts if it is so. Otherwise, 
it rejects. 

Intuitively, the computation of w, 1 |= ip is done recursively as follows. 
The automaton A^ "consists of" the automata A v for all sub-formula <p of 
ip, including A e to represent the empty formula e. 

• The automaton A e accepts every data words. 

• If ip = aip, then check whether the current label is a. If it is not, then 
A rejects immediately. Otherwise, A^ proceeds to run A^. 

• If ip — (p V <//, then A,j, nondeterministically chooses one of A v or A^ 
and proceeds to run one of them. 

• If ip — <pA<p', then A^p splits its computation (by conjunctive branching) 
into two and proceed to run both of A v and A^. 

• If ip = X(/9, then Af moves to the right one step. If it reads the right- 
end marker, then the automaton rejects immediately. Otherwise, it 
proceeds to run A v . 

• If ip =] <f, then A^ checks whether the data value seen by its head 
pebble is the same as the one seen by the second last placed pebble. If 
it is not the same, then it rejects immediately. Otherwise, it proceeds 
to run A v . 

• If -0 =4, (p, then A^ places a new pebble and proceeds to run A v . 

• If ip = tpVtp', then Af it runs A/v^ax^iv))- 

• If ip = -up, then A^, runs A v . If A v accepts, then A^ rejects. Other- 
wise, A$ accepts. 

Note that since fqr(</?) = k, on each computation path then the automaton 
A^ only needs to place the pebble k times, thus, A$ requires only k + 1. It 
is a straight forward induction to show that L(A^) = L(ip). □ 
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Our next results deals with the expressive power of LTL{(E,X,U) based 
on the freeze quantifier rank. It is an analog of the classical hierarchy of first 
order logic based on the ordinary quantifier rank. We start by defining an 
LTLj(S,X, U) sentence for the language IZ^ defined in Subsection 12 .21 

Lemma 17 For each k = 1, 2, 3, . . there exists a sentence ipk in LTL[(E, X, if) 
such that L{ip k ) = IZ^ and 

• fqr(ipi) = 1; and 

• fqr(ipk) — k — 1, when k > 2. 

Proof. First, we define a formula tpk such that fqr(<^^.) = k — 1 and for every 
data word w = (J) • • • (J ) , for every i = 1, . . . , n, 

w, i \= di ifk if and only if Qj • • • (° J 6 Tl\. (3) 

We construct <pk inductively as follows. 

• (p x := X(-i t) A -n(XTrue). 

• For each k = 1, 2, 3, . . ., 

<p k+1 : = X(-. t) AX(|X((-T)U(T A^ fc ))) 

Note that since fqr(^i) = 0, then for each k = 1,2, . . ., fqr(yjfc) = k — 1. 

Assuming first that ipk satisfies the property in Equation [31 the desired 
sentence ipk is defined as follows. 

• fa :=| (X(-. t) A -i(XTrue)). 

• For each k = 2,3, . . ., 

ip k := |(x(-T))Ax(|x((-t)u(TA^- 1 ))) 

Since fqr(<£> fc _i) = k — 2, then fqr(/0fc) = k — 1. 

Now we want to show that the formula (p k satisfies Equation [31 The 
proof is by induction on k. The base case, k — 1, is trivial. Suppose, for the 
induction hypothesis, the formula (pk satisfies Equation [3J 
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The induction step is as follows. Let w = yj •••(/)■ We have the 
following chain of application of the semantics of LTL. 

w,i \=di fk+i 
t 

w,i K x(-.t)ax(|x((-.t)u(T A^ fc ))) 
t 

w,i (=* X(--T) and w,i K x ( I x ((- T)U(T A<Pk))) 
For the first part, we have 

w, i \= di X(-i t) if and only if d> ^ d i+1 (4) 
Now we evaluate the second part. 

W,i x ( I X((-i t)U(t A^fc))) 

u;,z + l |=* ( i x ((- t)U(t A^ fc ))) 
t 

w,i + i K +1 x((- t)u(T a^,.)) 
t 

w } i + 2 K +1 (-T)u(ta^.) (5) 
Equation [5] holds if and only if there exists j such that i + 2 < j and 
1- w,j (=*+it A<^fc, 

2. tw, j' -. t, for each / = i + 1, . . . , j - 1. 

By the semantics of LTL and the induction hypothesis, Clause 1 holds if and 
only if dj = d i+ i and (J.) • • • y J G Tl\. The meaning of Clause 2 is g^- 7^ dj+i, 
for each j' = 2 + 1, . . . , j — 1. Both clauses, together with Equation [U means 
that (J) • • • (J) £ T^t+x- This completes the induction hypothesis. □ 

Lemma 18 For each k = 1, 2, . . i/ie language TZ^+i ^ s n °t expressible by a 
sentence in LTL[(T,, X, U) of freeze quantifier rank k — 1. 
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Proof. By Theorem^! Tlt+i ls n °t accepted by weak k-PA, thus, it is also not 
accepted by top-view fc-PA. Then, by Theorem [HI T^t+i ls n °t expressible 
by LTL^E, X, U) sentence of freeze quantifier rank k — 1. □ 

Combining both Lemmas [T7] and [181 we obtain the following strict hier- 
archy of LTL^(E, X, U) based on its freeze quantifier rank. 

Theorem 19 For each k = 1, 2, . . the class of sentences in LTL^(E, X, If) 
of freeze quantifier rank k + 1 is strictly more expressive than those of freeze 
quantifier rank k. 

6 Top view weak /c-PA 

In this section we are going to define top view weak PA. Roughly speaking, 
top view weak PA are weak PA where the equality test is performed only 
between the data values seen by the last and the second last placed pebbles. 
That is, if pebble i is the head pebble, then it can only compare the data 
value it reads with the data value read by pebble (i + 1). It is not allowed 
to compare its data value with those read by pebble (i + 2), (i + 3), . . . , k. 

Formally, top view weak k-PA is a tuple A = (E, Q, q , fi, F) where 
Q, q , F are as usual and \i consists of transitions of the form: {%, a, V, q) — > 
(q', act), where V is either or {i + 1}. 

The criteria for the application of transitions of top view weak k-PA is 
defined by setting 

y _ f 0, if a>o(i+i) 7^ a e(i) 

\ {i + 1}, if a 6 (i +1 ) = a#(i) 

in the definition of transition relation in Subsection 12.11 Note that top view 
weak 2-PA and weak 2-PA are the same. 

Remark 20 We can also define the alternating version of top view weak 
k-PA. However, just like in the case of weak k-PA, alternating, nondetermin- 
istic and deterministic top view weak k-PA have the same recognition power. 
Furthermore, by using the same proof presented in Section HJ it is straight- 
forward to show that the emptiness problem, the labelling problem, and the 
data value membership problem have the same complexity lower bound for 
top view weak k-PA, for each k — 2, 3, . . .. 

The following theorem is a stronger version of Theorem [TJ 
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Theorem 21 For every top view weak k-PA A, there is a one-way alternat- 
ing 1-RA A' such that L(A') = L(A). Moreover, the construction of A' is 
effective. 

Proof. The proof is a straightforward generalization of the proof of The- 
orem [3 Each placement of a pebble is simulated by "Guess-Split-Verify" 
procedure. Since each pebble i can only compare its data value with the one 
seen by pebble {i + 1), A' does not need to store the data values seen by peb- 
bles (i + 2), . . . ,k. It only needs to store the data value seen by pebble + 
thus, one register is sufficient for the simulation. □ 

Following Theorem [2TJ we immediately obtain the decidability of the 
emptiness problem for top view weak k-PA. 

Corollary 22 The emptiness problem for top view weak k-PA is decidable. 

Since the emptiness problem for ordinary 2-PA (See [TUI Theorem 4]) 
and for weak 3-PA is already undecidable, it seems that top view weak PA 
is a tight boundary of a subclass of PA languages for which the emptiness 
problem is decidable. 

Remark 23 In [16 J it is shown that for every sentence ip G LTL}(£, X,U), 
there exists a weak k-PA A^, where k = fqr(^) + 1, such that L(A^) = L(ip). 
We remark that the proof actually shows that the automaton Af is top view 
weak A;-PA. Thus, it shows that the class of top view weak A;-PA languages 
contains the languages definable by LTL|(S,X,U). 

7 Top view weak PA with unbounded num- 
ber of pebbles 

This section contains our quick observation on top view weak PA. We note 
that the finiteness of the number of pebbles for top view weak PA is not 
necessary. In fact, we can just define top view weak PA with unbounded 
number of pebbles, which we call top view weak unbounded PA. 

We elaborate on it in the following paragraphs. Let A = (£, Q, go, /i, F) 
be top view weak unbounded PA. The pebbles are numbered with the num- 
bers 1, 2,3,.. .. The automaton A starts the computation with only pebble 1 



27 



on the input word. The transitions are of the form: (cr,x,q) (j ; 3 -^), 
where x £ {0> 1} an d QiPi ac ' t are as m the ordinary weak PA. 

Let w = (^j) ■ • • (^") be an input word. A configuration of A on <w> is a 
triple [i, q, 9], where i G N, q G Q, and # : N — >• {0, 1, . . . , n, n+1}. The initial 
configuration is [l^o^o], where 9 Q (1) = 0. The accepting configurations are 
defined similarly as in ordinary weak PA. 

A transition (a, x,p) — * P applies to a configuration [i,q,9], if 

(1) p = q, and a e{i) = a, 

(2) X = 1 if a>o(i-i) = ae(i), and x = if a 6 (i-i) ^ ag^, 

Similarly, the transition relation h can be defined as follows: [i, q, 6] \- A 
[i', q', 9'}, if there is a transition a — > (p, act) G \i that applies to [i, q, 9} such 
that q' = p, for all j < i, 9'(j) = 0(j), and 

- if act = right, then %' — i and 9'(i) = 9(i) + 1, 

- if act = lift-pebble, then i' — i — 1 

- if act = place-pebble, then i! = % + 1, 9'(i + 1) = 0'(i) = 6>(i). 

The acceptance criteria can be defined similarly. 

It is straightforward to show that 1-way deterministic 1-RA can be sim- 
ulated by top view weak unbounded PA. Each time the register automaton 
change the content of the register, the top view weak unbounded PA places 
a new pebble. 

Furthermore, top view weak unbounded PA can be simulated by 1-way 
alternating 1-RA. Each time a pebble is placed, the register automaton per- 
forms "Guess-Split- Verify" procedure described in Section [3J Thus, the 
emptiness problem for top view unbounded weak PA is still decidable. 

8 Concluding remark 

In this paper we study pebble automata for data languages. In particular, 
we establish a fragment of PA languages for which the emptiness problem is 
decidable, the so called top view weak PA. As shown in this paper, top view 
weak PA inherit some nice properties mentioned in Section [TJ 

1. Expressiveness: Top view weak PA strictly contain the languages ex- 
pressible by LTL{(£, X, U). 
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2. Decidability: The emptiness problem is decidable. 

3. Efficiency: The model checking problem, that is, testing whether a 
given string of length n is accepted by a specific deterministic top view 
weak A;-PA can be solved in 0(n k ) computation time. 

4. Closure properties: Top view weak /c-PA languages are closed under all 
boolean operations. 

5. Robustness: Alternation and nondeterminism do not add expressive 
power to top view weak /c-PA languages. 

There are still lots of work to be done. In order to be applicable in program 
verification and XML settings, the model should work be infinite strings 
and unranked trees, respectively. Thus, the question remains whether it is 
possible to extend top view weak PA to the settings of infinite strings and 
unranked trees, while still preserving the five properties mentioned above. 

Acknowledgment. The author would like to thank Michael Kaminski for 
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A Counter Automata 

A Minsky k-counter automata (CA), with e-transitions and zero testing, is a 
tuple A = (£, Q, qo, 5, F), where 

• X is a finite alphabet; 

• Q is a finite set of states; 

• q is the initial state; 

• 5 C Q x (S U {e}) x L x Q is a transition relation over the instruction 
set L = {inc, dec, if z} x {1, . . . , k}; 

• F C Q is the set of accepting set, such that q' ^ F whenever (q, e, I, q') 6 
5. 
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Given a word w = o\ ■ ■ ■ a n G E*, a configuration of A is a triple [i,q, v] 
where < i < n, q E Q and a counter valuation v : {1, . . . , k} — > N, where 
N is the set of natural number {1, 2, 3, . . .}. 

The initial configuration is [0, go, v o] where Vo(j) = for each j — 1, . . . , k. 
The run of A on is a sequence [0, go, W|, [1> 9ij w i]> • • • , [ n , <Zn> w n] where for 
each i — 0, . . . , n — 1, there exists a transition (g^, cr j+i, Z, gi+i) G 5 and 

• if Z = (inc, j) for some j = 1 . . . , k, then v i+ i(j) = Vi(j) + 1 and for 
all other f ^ j, v i+1 (f) = Vi(j'). 

• if I = (dec,j) for some j = l...,k, then vi(j) > and = 
Vi(j) - 1 and for all other j' ^ j, v i+1 (f) = Vi(j'). 

• if I = (ifz, j) for some j — 1 . . . , k, then Vi(j) = and = Vi. 

The word w is accepted by A if q n G F. As usual, we denote by L(^4) the 
set of all words over E accepted by A. 

We say that the automaton A is incrementing if its counters may erro- 
neously increase at any time. More precisely, The run of an incrementing A 
on w is a sequence of configurations [0, go, Vq], [1, q%, Vi), . . . , [n, q n , v n ] where 
for each i — 0, . . . , n — 1, there exists a transition (gj, a"i+i, /, gi+i) G <5 and 

• if I = (inc, j) for some j = 1 . . . , k, then v i+1 (j) > ^(j) + 1 and for 
all other j' ^ j, Vi+iO'') > ^(i')- 

• if I = (dec,j) for some j = l...,k, then vi(j) > and v i+ i(j) > 
Vi(j) - 1 and for all other j' ^ j, v i+1 (f) > v i {j r ). 

• if / = (ifz, j) for some j = 1 . . . , k, then ^(j) = and for all j' = 
l,...,k, v i+1 (f) > Vi(j'). 

Theorem 24 [6, Theorem 2.9] (See also HH Theorem 6] and (Lfl) The 
nonemptiness problem for incrementing counter automata is decidable, but 
not primitive recursive. 

B Register automata 

We are only going to sketch roughly the definition of register automata. 
Readers interested in its more formal treatment can consult j6j [9] . In essence, 
k register automaton, or, shortly fc-RA, is a finite state automaton equipped 
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with a header to scan the input and k registers, numbered from 1 to k. Each 
register can store exactly one data value from D. The automaton is two-way 
if the header can move to the left or to the right. It is alternating if it is 
allowed to branch into a finite number of parallel computations. 

More formally, a two-way alternating /c-RA over the label E is a tuple 
A = (E, Q, g , u Q , /i, F) where 

• Qo, <7o £ Q and F C Q are the finite state of states, the initial state 
and the set of final states, respectively. 

• uq = ai ■ ■ ■ at is the initial content of the registers. 

• /i is a set of transitions of the following form. 

i) (q, a) — > q' where a G {<, >} and q, q' G Q. 

That is, if the automaton A is in state q and the header is currently 
reading either of the symbols <, >, then the automaton can enter 
the state q'. 

ii) (q, a, V) — > q' where a G E, V C {1, . . . , k} and q, q' G Q. 

That is, if the automaton A is in state q and the header is currently 
reading a position labeled with a and V is the set of all registers 
containing the current data value, then the automaton can enter 
the state q'. 

Hi) q — > (q'i I) where I C {1, . . . , k} and q, q' G Q. 

That is, if the automaton A is in state q, then the automaton 
can enter the state q' and store the current data value into the 
registers whose indices belong to /. 

iv) q — > (q± A • • • A qi) and q — > (qi V • • • V qi) where i > 1 and q, q' G Q. 
That is, if the automaton A is in state q, then it can decide to per- 
form conjunctive or disjunctive branching into the states q±, . . . , q^. 

v) q — > (g', act) where act G {left, right} and q, q' G 

That is, if the automaton A is in state q, then it can enter the 
state q' and move to the next or the previous word position. 

A register automaton is called non deterministic if the branchings of state 
(in item (iv)) are all disjunctive. It is called one-way if the header is not 
allowed to move to the previous word position. 
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A configuration 7 = [j, q, b\ ■ ■ ■ bj.] of the automaton A consists of the 
current position of the header in the input word j, the state of the automaton 
q and the content of the registers &i The configuration 7 is called 

accepting if the state is a final state in F. 

From each configuration 7, the automaton performs legitimate compu- 
tation according to the transition relation and enters another configuration 
7'. If the transition is branching, then it can split into several configurations 

Tl) ■ ■ ■ ) 1m- 

Similarly, we can define the notion of leads to acceptance for a configura- 
tion 7 as follows. 

• Every accepting configuration leads to acceptance. 

• If 7' is the configuration obtained from 7 by applying a non-branching 
transition, then 7 leads to acceptance if and only if 7' leads to accep- 
tance. 

• If j[, . . . , j' m are the configurations obtained from 7 by applying a dis- 
junctive branching transition, then 7 leads to acceptance if and only if 
at least one of j[, . . . , 7^ leads to acceptance. 

• If j[, . . . , j' m are the configurations obtained from 7 by applying a con- 
junctive branching transition, then 7 leads to acceptance if and only if 
all of 7^, ... , 7^ lead to acceptance. 

An input word w is accepted by A if the initial configuration leads to accep- 
tance. As usual, -^(^4) denotes the language accepted by A. 

C Generalization of Theorem [7] 

Let A = (Q,qo, n, F) be a weak fc-PA. We will show how to construct one- 
way alternating (k — 1)-RA A'. For our convenience, we assume that A is 
deterministic. We also assume that A behaves as follows. 

• For every configuration 7 of A, there exists a transition in [i that applies 
to it. 

• Only pebble k can enter a final state and it does so only after it reads 
the right-end marker >. 
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• For every i = 2, . . . , k, immediately after pebble i moves right, peb- 
ble z — 1 is placed. 

• For every i = 1, . . . ,k — 1, pebble % is lifted only when it reaches the 
right-end marker >. 

• For every i = 1, — 1, immediately after pebble i is lifted, peb- 
ble + moves right. 

See Subsection ID. II on how this normalization can be done. 

We also assume that the set of states Q is partitioned into Qi U • • • U Qk 
where Qi D Qj whenever i ^ j and Qi is the set of states when pebble % is in 
control. 

The automaton A' = (Q', q' , Uq, //, F') is defined as follows. 

• The set of states is Q' = QUQ 2 UQ 3 UQUQ x Q, where Q = {q \ q G Q} 
and Q x Q = {(q,p) \p,q e Q}. 

• The initial state is q' = qo e Qk- 

• The initial assignment is 

• The set of final states is F' = F U {(q, q) : q G Q}. 

For our convenience, we number the registers of A' from 2 to k, not from 1 
to (k — 1). The set of transitions //' consists of the following. 

• For i = k — 1,...,1, we have the following transitions. 

1. For each transition (i, a, V, q) — > (q', right) G /i, there are transi- 
tions ((q,p),a, V) — > (g',p) G // for all p G Qi+i- 

2. For each transition (i,P,V,q) — > (g', place-pebble) G //, there 
are the following transitions in //'. For every p G Qi+i, 




(Pj,p) A (g',Pj) for every pj G 



• For i = k, there are the following transitions in p! . 
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1. For each transition (k, a, 0, q) — > (g', right) G there is a transi- 
tion (g, a, 0) -> (g') G //. 

2. For each transition (k, a, 0, g) — > (q', place-pebble) G /i, there 
are the following transitions in //. 

9 V 

-> pj A (g',Pj) for every G Q fe 
We can show the following proposition by straightforward induction on i. 

Proposition 25 Letw = (^) • • • (^") &e a Y.-data word. Fori = 1, . . . , k — 1, 

there exists an i-run [i,qi,9i] h* [i, q 2 ,9 2 ] 0/ -4 on w and [i, g 2 , ^2] \~ [i + 
1)93)^3] an d on ly if the configuration [0(i), ^3), n 2 • • • u^] of A' on w 
leads to acceptance, where Uj = a^(j); f or j — i + 1, ■ ■ ■ ,k. 

Then, by the definition of //, we can easily deduce the following. For each 
£=l,...,n, 

[k, q u 61] \~ A [k - 1, q 2 , 9 2 ] \~* A [k - 1, g 3 , 6> 3 ] \~ A [k, g 4 , 4 ] \~ A [k, q 5 , 5 ] 

is a Axrun of A on iy, where 9±(k) = 9 2 (k) = 9 3 (k) = 9 4 (k) = £ and 9 5 (k) = 
e+lajid9 2 (k-l)=e,9 3 (k-l)=n + l if and only if 

[U,#*-Vi] I- [*,&,#*- 2 a/] 

[4(?i,?4),# fc - 2 a/] h [£,g 4 ,# fc -V] 

[4(?i,94),#*- 2 a<] h [*,(<&, g 4 ),# fc - 2 a*] 
[£,g 4 ,# fe -%] h [£ + l,g 5 ,# fe - 2 a £ ] 

and the configuration [£, (g 2 , 54), # fc ~ 2 a£] leads to acceptance. 

Now, the equivalence between L(A) and -L(»4 / ) follows immediately. 

D Equivalence between alternating and de- 
terministic one-way weak fc-PA 

For every one-way alternating weak /c-PA, we will construct its equivalent 
one-way deterministic weak /c-PA. This is done in two steps. 
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1. First, we transform the one-way alternating weak k-PA into its equiv- 
alent one-way nondeterministic weak k-PA. 

2. Then, we transform the one-way nondeterministic weak k-PA into its 
equivalent one-way deterministic weak k-PA. 

We present step 2 first. 

D.l From nondeterministic to deterministic 

We start with the simple case. We will show how to determinize nonde- 
terministic weak 2-PA. The idea can be generalized to arbitrary number of 
pebbles. 

Let A = (Q,q ,F, fx) be a nondeterministic weak 2-PA. We start by nor- 
malizing the behavior of A as follows. 

Nl. For every configuration 7 of A, there exists a transition in ji that applies 
to it. 

N2. Only pebble 2 can enter a final state and it does so only after it reads 
the right-end marker >. 

N3. Immediately after pebble 2 moves right, pebble 1 is placed. 

N4. Pebble 1 is lifted only when it reaches the right-end marker >. 

Such normalization can be done by adding some extra states to A. This 
normalization N4 is especially important, as it implies that nondeterminism 
on pebble 1 is now limited only to deciding which state to enter. There is no 
nondeterminism in choosing which action to take, i.e. either to lift pebble 1 
or to keep on moving right. 

Next, we note that immediately after pebble 1 is lifted, there can be two 
choices of actions for pebble 2: 

- to place pebble 1 again; or 

- moves pebble 2 to the right. 

The following fifth normalization is supposed to handle this situation: 
N5. Immediately after pebble 1 is lifted, pebble 2 moves right. 
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In other words, while pebble 2 is reading a specific position, pebble 1 makes 
exactly one pass, from the position of pebble 2 to the right end of the input, 
instead of making several rounds of passes by placing pebble 1 again imme- 
diately after it is lifted. Since there are only finitely many states, there can 
only be finitely many passes. So, the normalization N4 can be achieved by 
simultaneously simulating all possible passes in one pass. 

With the normalization N1-N5, there is no nondeterminism in choosing 
which action to take for pebble 2. The same as for pebble 1, the nondeter- 
minism for pebble 2 is now limited only in deciding which states to take. 
This is summed up in the following remark. 

Remark 26 For each i — 1,2, if (i,P,V,p) — > (g^actx) and (i,P,V,p) — > 
(<72,act2), then acti = act2- 

Now that the nondeterminism is reduced to deciding which state to enter, 
the determinization of A becomes straightforward. Similar to the classical 
proof of the equivalence between nondeterministic and deterministic finite 
state automata, we can take the power set of the states of A to determinis- 
tically simulate A. 

Now the normalization steps N1-N5 can be performed similarly for weak 
A:-PA A. 

NT. For every configuration 7 of A, there exists a transition in \i that applies 
to it. 

N2'. Only pebble k can enter a final state and it does so only after it reads 
the right-end marker >. 

N3'. For each i = 2, . . . , k, immediately after pebble i moves right, peb- 
ble (i — 1) is placed. 

NT. For each i = 1, . . . ,k — 1, pebble % is lifted only when it reaches the 
right-end marker >. 

N5'. For each % — 1, . . . , k— 1, Immediately after pebble % is lifted, pebble i+1 
moves right. 

Such normalization results in reducing the nondeterminism to deciding which 
state to enter. Then, the determinization of A can be done just like in the 
classical case as in the case of weak 2-PA described above. 

The following are the details of the determinization of A = (£, Q, go, F)- 
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Let P, V C {1, . . . , k}. For a subset S C Q, we define the following: 

Ei,p,v(S) — {q '■ 3g' G S such that (i, P, V, g') — > (q, act) G /i}; 
^.j,p,v(S) = ac "t where (i, P, V, q) — > (q', act) for some q G 5* and </ G Q. 

By Remark [261 above. Aj i p i y(<S') is well defined. Furthermore, F^py is mono- 
tone, that is, if S C 5", then E itP y(S) C E it py(S'). 

Now we present the construction of a deterministic, weak fc-pebble au- 
tomaton A' equivalent to A. Let A' = (Q', q' , F', //) where 

- Q' = 2«; 

- q'o = {voh 

- F' = {S CQ : Sf)F ^®}; 

- y! consists of the following transitions. For each i G {1, . . . , k}, P, V C 
{i + 1, . . . , k} and 5* C Q, 

(i,P,V,S) -> (E iiPjV (5),A,p,v(5)) e //. 

Recall that an i-run is a run from an i-configuration to an i-configuration in 
which pebble i + 1 is never lifted. We are going to use the following Claim [T] 
to prove that L(A') = L(A). 

Claim 1 Let i = 1, . . . , k. Let w G X* and 9\, 9 2 be pebble assignments on 
w. 

1. For every set of states S\,S 2 Q Q, if [i, Si, #1] h* [i, S2, # 2 ] an i-run 
of A' , then 

(J {7 : [i, q u 9i] \-* A 7 is an i-run} = {[i, q 2 , 9 2 ] : g2 G S 2 }. 

9lGSi 

For every state qi,q 2 Q Q, if [i,qi,9i] h* [i, q 2 ,9 2 ] is an i-run of A, 
then for all Si C Q such that q\ G S\, there exists S 2 C Q such that 
q 2 G S 2 and [z,Si,#i] h* [i, S 2 ,9 2 ] is an i-run of A' . 
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Proof. Let w, $i, 6 2 be as above. The proof of the claim is by induction on 
i. The base case, i — 1, is the same as the standard finite state automaton, 
thus, omitted. 

For the induction hypothesis, we assume that the claim is true for the 
case of i — 1. To proceed with the induction step, we prove the claim for the 

case i. 

We start by proving (1). Let S 1: S 2 Q Q. Assume that 

[i,S 1 ,9 1 ] h* [i,S 2 ,9 2 \. 

By our normalization of A, the resulting automaton A' from our construction 
is also normalized as the automaton A. Thus, an i-run of A' is a repeated 
sequence of transitions relations of the form: 

[i, R u Ai] h [i - 1, R 2 , A 2 ] h* [i - 1, R 3 , A 3 ] h [i, i? 4 , A 4 ] h- [i, i? 5 , A 5 ], 

where 

some transition (i, P l5 Vi, Ri) — > (i? 2 , place-pebble) G ^' is applied to 
obtain the transition relation [i, R±, Ai] h [« — 1, i? 2 , A 2 ], 

the transition relation [i — 1, R 2 , A 2 ] h* [i — 1, R 3 , A3] is an {i — l)-run 
of ,4', 

c) some transition (i, P 2 , V 2 , R 3 ) — > (i? 4 , lift-pebble) G // is applied to 
obtain the transition relation [i, R 3 , A 3 ] h [i, i? 4 , A 4 ], 

d) some transition (i, P 3 , V 3 , i? 4 ) — > (i? 5 , right) G // is applied to obtain 
the transition relation [i, i? 4 , A 4 ] h [i, R 5 , A 5 ]. 

Thus, to prove part (1), it suffices to prove the following four equations. 

(J {7: [*,pi,Ai] h x7 } = {[*-l,p2,A 2 ] :p 2 eR 2 } (6) 

(J {7 : [i - l,p 2 , A 2 ] \~* A 7 is an (i - l)-run} = {[i - l,p 3 , A 3 ] : p 3 € R 3 } (7) 

|J {7: [i-l.p3.A3] h,i 7} = {[«,p 4 ,A 4 ] :p 4 G i? 4 } (8) 

(J {7 : [i,P4,A 4 ] h A 7} = {[*,pb,Ab] :p 5 € #5} (9) 



40 



Proof of (ED: By item (a) above, there is a transition (i, Pi,V\, R\) — > 
(i? 2 , place-pebble) G fi' . By the construction of p! that P 2 = -Ki,Pi,Vi(-Ri), 
we immediately have Equation [61 

Proof of '([7]): By item above, [i — 1,^2,^2] I - * [z — l,i?3,A3] is an {i — l)-run 
of A'. Equation [7| follows from the induction hypothesis. 

Proof of ([5]): By item (c) above, there is a transition (i, P 2 , V2, R3) — > 
(P 4 , lift-pebble) G p! . By the construction of p! that P 4 = E ijP2 y 2 (R 3 ), 
we immediately have Equation [HI 

Proof of <Q: By item fdj above, there is a transition (z, P 3 , V3, P 4 ) — ► 
(P5, right) G //. By the construction of p! that P5 = E it p 3 y 3 ( y R 4: ), we 
immediately have Equation [91 

The proof of part (2) of our claim is very similar to the one of part (1). 
For completeness, we present it here. Let q\,q2&Q and 

[i,gi,0i] [i,q 2 ,9 2 ] 

be an i-run of A. 

By our normalization of A, an i-run of A' is a repeated sequence of 
transitions relations of the form: 

[i,Pi, AJ l,p 2 , A 2 ] H* [i - l,p 3 , A 3 ] h [i,p 4 , A 4 ] h [i,p 5 , A 5 ], 

where 

a) some transition (i, Pi,Vi,pi) — > (p 2 , place-pebble) G p is applied to 
obtain the transition relation Ai] h [i — 1,P2, A 2 ], 

&j the transition relation [i — l,p2, A 2 ] H* [i — 1,P3, A3] is an (i — l)-run of 
-4'. 

c) some transition (i,P 2 , T^,p 3 ) — > (p 4 , lift-pebble) G // is applied to 
obtain the transition relation [i — l,p 3 , \ 3 ] h [i — l,p 4 , A 4 ], 

c?j some transition (z,P3,V3,p 4 ) — * (ps, right) G p! is applied to obtain 
the transition relation [z,p 4 , A 4 ] h [i,p$, X5). 

The proof of part (2) follows from the following. 
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• For all Ri C Q such that pi G Pi, there exists P 2 C Q such that 
p 2 e R2 and [i, Pi, Ai] \~ A > [i - 1, P 2 , A 2 ]. 

This immediately follows from the fact that p 2 G Ei i p 1 y 1 (Ri) and 
(i,Pi,Vi,i?i) -> (Ei iPltVl (Ri), place-pebble) G //. 

• For all P 2 C Q such that p 2 G P 2 , there exists fi 3 C Q such that 
P3 G -R3 and [i — 1, P 2 , A 2 ] \-* A , [i — 1, P3, A3] is an (i — l)-run. 

This follows from the induction hypothesis. 

• For all -R3 C Q such that p 3 G P3, there exists P 4 C Q such that 
j9 4 G P 4 and [i - 1, P 3 , A 3 ] h x / [i, P 4 , A 4 ]. 

This immediately follows from the fact that p 3 G E iyP2 y 2 (R 3 ) and 
(i, P 2 , V 2 , P 3 ) -> {E ijP2 y 2 {R 3 ), lift-pebble) G //. 

• For all P 4 C Q such that p 4 G P 4 , there exists P5 C Q such that 
j9 5 G P 5 and [i, P 4 , A 4 ] h^, [i, R 5 , A 5 ]. 

This immediately follows from the fact that p 4 G E ijP3 y 3 (R 4 ) and 

(i,P 3 ,V 3 ,R 4 ) -> (^3^3(^4), right) G //. 

□ 

D.2 From alternating to nondeterministic 

Let A = (E, Q, g , A*, P, ^ ) be one-way alternating weak k-PA. Adding some 
extra states, we can normalize A as follows. 

• For every p G U, if (i, a, V,p) — > (q, act) G //, then act = stay. 

• Every pebble can be lifted only after it reads the right-end marker >. 

• Only pebble k can enter a final state and it does so only after it reads 
the right-end marker >. 

We assume that Q is partitioned into Q\ U • • • U Qk where Qi is the set 
of states, where pebble % is the head pebble, for each % — 1, . . . , k. We can 
further partition each Qi into four sets of states: <5i,stay, <5«,right, Qi, P iac e) 
<5i,iift such that for every i, a, V, q and p, 

• if q G Qi )S tay and (i, a, V, q) — > (p, act) G /i, then act = stay; 

• if q G <5i,ri g ht and (2, a, V, g) — > (p, act) G /i, then act = right; 
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• if g G <5i iP iace and (i, V, q) —> (p, ac "t) G A 4 ) then act = place-pebble; 

• if g G Qi,iift and (i, cr, V, q) — > (p, act) G /i, then act = lift-pebble. 
Now we define a nondeterministic weak A;- PA A! = (X, Q' , q' , /i', F'), where 

• Q' consists of states of the form (S k , Sk-i ■ ■ ■ , Sk-j) G 2 Qk x 2 Qfc - 1 x 
2Qk-j ; w here < j < /c — 1; 

• 5o = {<?o}; 

• F' = 2 F - {0}. 

The set // contains the following transitions. For every « = 1,2, ... ,k, for 
every V C {i + 1, . . . , k}, for every (Sk, Sk-i, . . . , Si) G Q' , for every a G £, 
we have the following transitions. 

• If contains a state q £ U, then 
(i,<7,V,(£fc,Sfc_i,...,iSi)) -> ((S , fc ,S , A ; _i,...,(S'i-{g})Uf/ (? ),stay) G // 
where C/q = {p | (i, a, V, q) — > (p, stay) G //}. 

• If Si contains a state g G Qi, s ta y and S (~}U = 0, then 

(i,<7,V, (S*, Sfc_i, . . . , iSi)) -> ((S k ,S k -i, . . . , (Si-{q})UN q ), stay) G // 
where iV g C {p | («, a, V, g) — ► (p, stay) G //}. 

• If Si contains a state g G <3j iP iace and fl Qj iS ta y = 0) then 

(i, a, V, (S k , S k -i, ...,$))-> ((S k: S k -i, ■ Si-{q}, {p}), place-pebble) G // 
where (i, a, V, q) — > (p, place-pebble) G /i. 

• If C Qj.right, then 

(i, a, V, (S k , S k -i, . . . , Si)) -> ((Sk, Sfc-i, . . . , 5-), right) G // 
where S- = {p | (i, a, V, g) — > (p, right) G /x and g G 5 fl Qi\. 

• U SiQ Q^iift, then 

(i, >, V, (S fe , Sfc-i, . . . , S m , S;)) -> ((S fe , S k -i, S i+1 UR), lift-pebble) G // 
where i? = {p | (i, a, V, g) — > (p, lift-pebble) G /i and g G Sj}. 
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The proof that L(A) = L(A') is pretty much similar to the one in the previous 
subsection. 

Let Sk, Sk-i, ■ ■ ■ ,Si and 6 such that 

[*,{*>}, 0o] ^ [i,(S k ,S k - 1 ,...,S i ),8]. 

For each j = k, k — 1, . . . , i, we define Oj to be restricted to the domain 
{k, k — 1, . . . , j}. Then, by straightforward induction on i, we can show that 

[k, g , #o] b'» ^ ^j]> for each j = k,k-l,...,i. 

Now we show the converse direction. Let be an assignment for peb- 
bles k, k — 1, . . . ,i and we denote by 9j the pebble assignment 6 restricted 
to the domain {k, k — 1, . . . , j} when j > i. Let Sk, Sk-i, ■ ■ ■ , Si be sub- 
sets of Qk, Qk-\i ■ ■ ■ i Qii respectively, and let Pk,Pk-i,Pi+i be an element of 
Qk, Qk-i, ■ ■ ■ ,Qi such that for each j — k, k — 1, . . . , i, 

• Pi i s v 

• [k, g , 0o] \~* A [j, g, Oj], for each g e Sj. 

Then, by straightforward induction on i, we can show that 

[Mgo}A] 1-1' [i,(Sk,S k -i,...,Si),9}. 
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